AWS Certified SysOps Administrator – Associate — Question 36

A company uses AWS Organizations to manage multiple AWS accounts. Corporate policy mandates that only specific AWS Regions can be used to store and process customer data. A SysOps administrator must prevent the provisioning of Amazon EC2 instances in unauthorized Regions by anyone in the company.
What is the MOST operationally efficient solution that meets these requirements?

Answer options

Correct answer: D

Explanation

The correct answer is D because a service control policy (SCP) is specifically designed to manage permissions across AWS Organizations, making it the most efficient and effective method to enforce restrictions at an organizational level. Options A, B, and C involve more operational overhead and do not provide the same level of centralized control, as they require management in individual accounts or through separate monitoring and termination processes.